<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit in Installation</title>
    <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197227#M3105</link>
    <description>&lt;P&gt;I would first attempt to re-install Splunk.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Mar 2014 14:21:05 GMT</pubDate>
    <dc:creator>aelliott</dc:creator>
    <dc:date>2014-03-24T14:21:05Z</dc:date>
    <item>
      <title>License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197220#M3098</link>
      <description>&lt;P&gt;Good morning everybody, &lt;BR /&gt;
as reported in the subject I have a license limit violation in my Splunk installation with unavailability of searching anything. I verified that in the last 30 days I didn't exceed the 500 MB daily in the log.&lt;/P&gt;

&lt;P&gt;Why I cannot use the search feature and why I'm receiving the license violation error if I'm inside the 500 MB limit (I'm currently respecting the license agreement of the Splunk free version)?&lt;/P&gt;

&lt;P&gt;Thank you very much for your assistance.&lt;/P&gt;

&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 07:22:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197220#M3098</guid>
      <dc:creator>marcosciarrone</dc:creator>
      <dc:date>2014-03-21T07:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197221#M3099</link>
      <description>&lt;P&gt;From the sound of it, you are not within your 500 MB/day. How did you check? You are aware that the license is counted towards the uncompressed size of the incoming logs, not how much space they take on disk on the indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 08:01:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197221#M3099</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-21T08:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197222#M3100</link>
      <description>&lt;P&gt;It's also not calculated on a per-index basis but rather over all (non-internal) indexes combined... hence if you have three indexes getting 200MB each per day you're over 500MB in total daily.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 14:22:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197222#M3100</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-21T14:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197223#M3101</link>
      <description>&lt;P&gt;Thank you for the reply. I have only one index with only one device feeding the syslog. I checked the size of the log from the search menu (i do not remember the right menu) and i created a graph with the amount of the index over the last 30 days. I'm always under 180 mb. I can confirm that the size is below 200 mb because i've another syslog with the same data.&lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;

&lt;P&gt;Thank you very much,&lt;BR /&gt;
Marco&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 14:35:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197223#M3101</guid>
      <dc:creator>marcosciarrone</dc:creator>
      <dc:date>2014-03-21T14:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197224#M3102</link>
      <description>&lt;P&gt;For a more reliable view into your licensing volume take a look at Settings -&amp;gt; Licensing -&amp;gt; Usage Report -&amp;gt; 30 days, directly: &lt;A href="http://yourhost:8000/en-US/manager/search/licenseusage"&gt;http://yourhost:8000/en-US/manager/search/licenseusage&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 14:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197224#M3102</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-21T14:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197225#M3103</link>
      <description>&lt;P&gt;You are probably looking at the Compressed index size. Your data will be between 10% and 110%  based on the data compression ratio and unique columns in the data.. I recommend installing S.O.S. (splunk on splunk) app &lt;A href="http://apps.splunk.com/app/748/"&gt;http://apps.splunk.com/app/748/&lt;/A&gt;, it will give you much insight to these values (metrics dashboard i believe)&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 15:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197225#M3103</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-03-21T15:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197226#M3104</link>
      <description>&lt;P&gt;Dear all, thank you for your feedback.&lt;/P&gt;

&lt;P&gt;I installed Splunk SOS and I generated the report of the license usage for the last 30 days: The daily usage of the license is always below 200MB each day.&lt;/P&gt;

&lt;P&gt;Any suggestion? I cannot access the search yet.&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Marco&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 14:18:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197226#M3104</guid>
      <dc:creator>marcosciarrone</dc:creator>
      <dc:date>2014-03-24T14:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197227#M3105</link>
      <description>&lt;P&gt;I would first attempt to re-install Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 14:21:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197227#M3105</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-03-24T14:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197228#M3106</link>
      <description>&lt;P&gt;Ok but if I reinstall Splunk is there any risk I lost all my stored logs?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Marco&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 14:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197228#M3106</guid>
      <dc:creator>marcosciarrone</dc:creator>
      <dc:date>2014-03-24T14:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: License violation BUT NO INDEX IS EXCEEDING the 500 MB daily limit</title>
      <link>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197229#M3107</link>
      <description>&lt;P&gt;You would have to back up your configurations/ indexes before doing this. &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/11059/splunk-backup-and-restore-procedure"&gt;http://answers.splunk.com/answers/11059/splunk-backup-and-restore-procedure&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 14:59:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/License-violation-BUT-NO-INDEX-IS-EXCEEDING-the-500-MB-daily/m-p/197229#M3107</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-03-24T14:59:34Z</dc:date>
    </item>
  </channel>
</rss>

